CVE-2020-15935: Fortinet FortiADC

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.

Affected products

  • Fortinet FortiADC: from 5.0.0, up to and including 5.4.3; from 6.0.0, up to and including 6.0.1

Published 2021-11-02. Last modified 2026-06-17.